Build a Complete Open Source SIEM Stack in Just Minutes - SOCFortress Fast Track!

Поделиться
HTML-код
  • Опубликовано: 3 дек 2024

Комментарии • 23

  • @petarsimovic5628
    @petarsimovic5628 Месяц назад +5

    Really great automation, and also great support for #open-source community

  • @AliciaFernandez-zy2pn
    @AliciaFernandez-zy2pn Месяц назад

    You're exceptional....You finally listened

  • @SelienK
    @SelienK Месяц назад +3

    thank you very much. i really hope there will be a step-by-step guide to build siem stack cluster (index cluster, graylog cluster, ....)

  • @iowawizkid1
    @iowawizkid1 Месяц назад

    Way to GO dlo! I've been away for over a year and my wazuh is waay out of date. Looking forward to this quick deployment!

  • @adilhashmi7608
    @adilhashmi7608 Месяц назад +1

    Hope you give more information about the siem solution like how to collect logs and how to write custom rules and all

  • @chadmarkley
    @chadmarkley Месяц назад

    This is so WOW. Love it. But a question. Should I have been putting my docker stuff in the /opt directory all along!?

  • @jumpieva
    @jumpieva 5 дней назад

    at 5:34 This threw me off because the document shows the file as root_ca.pem but the script creates root-ca.pem. may want to correct that. Otherwise very helpful thank you!

  • @aniketsaha7273
    @aniketsaha7273 11 дней назад

    how can i connect a docker graylog with non-docker wazuh indexer ?? anyone help please......

  • @ederaam
    @ederaam Месяц назад

    What is the final and real video to installing Soc fortress. You have some videos..

  • @freeload101
    @freeload101 Месяц назад

    You beat met too it ! Can't wait to make it even more idiot proof in JAMBOREE :P THANK YOU SO MUCH!

  • @derekjohnson1592
    @derekjohnson1592 Месяц назад

    Really easy to install and get running but now I nave to get data into the system...? Where would we point to push logs to the system

  • @07markus
    @07markus Месяц назад +5

    why greylog and wazuh together?

    • @thienngo1560
      @thienngo1560 Месяц назад +1

      same question. :?

    • @marcioguedes2072
      @marcioguedes2072 Месяц назад +2

      They use graylog to make log normalization of wazuh fields, to interact with other threat intel sources and some other things.

    • @christopherpeterson6004
      @christopherpeterson6004 Месяц назад

      Graylog supports an agentless log ingestion input such as SYSLOG and manages the opensearch indexes as part of a fully open source ELK stack, whereas Wazuh depends on the agent to be installed.

  • @flightlessninja
    @flightlessninja Месяц назад

    I'm trying to deploy but after running docker compose all the containers start aside from graylog that reports it is unable to find mongodb. Can anyone point me in the right direction for this who have been able to deploy the stack. Many Thanks

    • @flashcrick7082
      @flashcrick7082 17 дней назад

      Same issues if you found any thing to fix it plz update me on it.

    • @miltiadiskandias7002
      @miltiadiskandias7002 2 дня назад

      So, I encountered the same problem. In my case the issue was mongo complaining for a CPU that does not support AVX. To verify do a docker ps, copy paste the mongo id and run "docker logs mongo_ID --follow". If it says the same message, then you have to verify that your CPU supports AVX, in my case it did so went to proxmox, used the correct CPU (host) and after restarting the whole process from scratch got rid of the mongodb problem.

  • @Games-zone945
    @Games-zone945 Месяц назад

    all containers are not starting
    like graylog

  • @alihasanmogal1199
    @alihasanmogal1199 Месяц назад

    Hey connector not working